RHSA-2026:35111HighCVSS 8.8

Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update

Published
July 2, 2026
Last Modified
July 22, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2026-32285 — github.com/buger/jsonparser: github.com/buger/jsonparser: Denial of Service via malformed JSON input CVE-2026-44740 — github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation CVE-2026-46680 — github.com/containerd/containerd: containerd: Privilege escalation via incorrect user ID handling CVE-2026-47262 — github.com/containerd/containerd: containerd: Denial of Service via maliciously crafted image leading to unbounded group parsing CVE-2026-50195 — github.com/containerd/containerd: containerd: Arbitrary code execution via CRI checkpoint image tag poisoning CVE-2026-53488 — github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin

🔗 References (10)